Multiple Vulnerabilities Discovered in libevent Affecting Ubuntu Systems

Multiple Vulnerabilities Discovered in libevent Affecting Ubuntu Systems

First seen 1 Sep 2026, 22:29 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

On September 1, 2026, Ubuntu published a security notice detailing multiple vulnerabilities in the libevent library, affecting Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS. Key issues include a use-after-free vulnerability (CVE-2026-63381) that could lead to denial of service or arbitrary code execution, and HTTP request smuggling (CVE-2026-63382). Additional vulnerabilities include out-of-bounds reads (CVE-2026-63383) and excessive resource consumption (CVE-2026-63384). The vulnerabilities were discovered by researchers Alexis Challande, Rajat Raghav, and Qiu Sihao, with all CVEs published on August 20, 2026. Users are urged to update their systems to mitigate these risks.

Key Points: • Five critical vulnerabilities identified in libevent affecting multiple Ubuntu LTS versions. • CVE-2026-63381 poses a risk of denial of service or arbitrary code execution. • Immediate updates are recommended to secure affected systems.

Timeline

2026-08-20
CVE-2026-63381 published
A use-after-free vulnerability in libevent could lead to denial of service or arbitrary code execution.
Ubuntu
2026-08-20
CVE-2026-63382 published
Improper handling of HTTP requests in libevent could result in HTTP request smuggling.
Ubuntu
2026-08-20
CVE-2026-63383 published
Malformed tagged RPC data in libevent could trigger an out-of-bounds read, causing denial of service.
Ubuntu
2026-08-20
CVE-2026-63384 published
Large payload lengths in tagged RPC data could lead to excessive resource consumption.
Ubuntu
2026-08-20
CVE-2026-63385 published
Improper handling of HTTP URIs in libevent could allow security restrictions to be bypassed.
Ubuntu
2026-09-01
Security notice published
Ubuntu published a security notice detailing multiple vulnerabilities in libevent affecting several LTS versions.
Linuxsecurity